The Role at a GlanceLocation: Markham, ON (Hybrid environment).Reporting To: Chief Information Officer (CIO).Mission: Lead the strategic and operational IT security program to protect healthcare and corporate data across Long-Term Care and Home Care sectors.Key ResponsibilitiesAs the CISO, you won't just be managing firewalls; you'll be building a culture of security. Your accountabilities include:Strategic Governance: Defining security policies aligned with NIST, SOC 2, and Zero Trust frameworks.Risk Management: Leading threat modeling and third-party risk management (TPRM) for vendors and cloud providers.Incident Response: Acting as the executive sponsor for the Cybersecurity Incident Response Program.Compliance: Ensuring strict adherence to Canadian healthcare privacy laws like PHIPA and PIPEDA.Technical Oversight: Overseeing identity management (Okta), cloud security (Azure/AWS), and EMR integrations (PointClickCare/AlayaCare).What They Are Looking ForThis is a senior-tier role requiring a minimum of 10+ years of progressive experience.Requirement TypeSpecificsMust-Haves10+ years in Cybersecurity; Healthcare sector experience; Microsoft & AWS cloud expertise.Tech StackMicrosoft ecosystem, Workday, ServiceNow, Okta, and EMR systems (PointClickCare).CertificationsCISSP, CISM, or CRISC (preferred).Soft SkillsAbility to translate "technical speak" into business risk for non-technical stakeholders.New FrontiersFamiliarity with AI risk mitigation (specifically Microsoft and Anthropic models).Why This Opportunity Stands OutImpact: You are protecting the data of vulnerable populations and the workforce that cares for them.Modern Infrastructure: The role involves working with Zero Trust architecture and multi-cloud environments.Stability: Extendicare has a 50-year history and offers a robust total rewards package.Important Application NoteSimilar to the Alamos Gold posting, Extendicare mentions they use AI tools to assist in reviewing applications. To ensure your profile reaches a human recruiter, make sure your resume explicitly highlights:Your senior leadership years (10+).Specific healthcare regulations you've worked with (PHIPA/PIPEDA).Keywords for their specific tech stack (e.g., Zero Trust, Okta, Azure).Does your background align more with the technical engineering side of security, or the policy and governance side?